Deployment
Getting an app from a laptop to a real address and keeping it there — hosting choices, domains, SSL, preview environments and zero-downtime releases.
84 posts · page 3 of 4
How to Send Email From Your App Without Landing in Spam
Password resets, receipts, and sign-up confirmations that land in spam — or never arrive — are one of the most common launch-week problems. What SPF, DKIM, and DMARC actually do, how to set them up for your domain, and why your app should never send mail itself.
Self-Hosting Next.js Without Vercel: What Works, What Breaks, What to Configure
Next.js runs anywhere Node.js does, and on a single server almost everything just works. The surprises: build-time environment variables, caching across instances, streaming behind a proxy, and a few Vercel-only conveniences. A practical guide to running Next.js on your own infrastructure.
Secrets Management Beyond .env Files
.env files are fine on a laptop and fragile everywhere else. Where secrets should live in production and CI, secret managers vs platform env vars, OIDC to remove long-lived CI credentials, rotation, least privilege, keeping secrets out of logs and AI agent context, and a practical maturity path.
Reverse Proxies Explained: Nginx, Caddy, and Traefik in Front of Your App
A reverse proxy sits between the internet and your app, handling TLS, routing, compression, and more. What reverse proxies do, how Nginx, Caddy, and Traefik differ, forwarded headers and trusting the real client IP, WebSockets and streaming, timeouts and body limits, and common 502/504 causes.
Replit Alternatives in 2026: What to Use Depending on Why You're Leaving
Replit bundles an AI agent, an editor, hosting, and a database. People leave for different reasons — cost, control, the agent, or outgrowing the platform — and each reason points to a different alternative. An honest guide to picking the right one.
Writing a Production Dockerfile for a Node.js App
The Dockerfile an AI tool writes usually works — and ships a 1.5 GB image running as root that ignores shutdown signals and leaks build secrets into its layers. A line-by-line production Dockerfile: multi-stage builds, layer caching, non-root users, signal handling, secrets, and health checks.
Preview Environments for Every Branch: How They Work and What They Cost
A preview environment gives every branch or pull request its own live URL, so changes are reviewed running rather than read as diffs. How they work, the hard part (databases), the ways to get one, and why they matter more when an AI agent is writing the code.
Postgres Migrations on Large Tables Without Downtime
The migration that took 40 ms in staging locked production for minutes. Postgres lock levels and the lock queue, lock_timeout with retries, which ALTER TABLE operations rewrite, CREATE INDEX CONCURRENTLY, NOT VALID constraints, safe NOT NULL, and batched backfills.
Postgres Major Version Upgrades: pg_upgrade, Logical Replication, and Minimal Downtime
Major versions change the on-disk format, so upgrading PostgreSQL isn't a package update. Dump/restore vs pg_upgrade (copy, link, clone) vs logical replication cutover; extension and collation pitfalls; sequences and DDL gaps in logical replication; statistics after upgrade; and a rehearsed runbook.
How to Back Up a Postgres Database — and Prove the Backup Works
A backup you've never restored is a guess. The three kinds of Postgres backup, how to take each one, where to store them, and a restore drill you can run in fifteen minutes to find out whether yours actually work.
How to Move a Replit App to Your Own Hosting
Replit is a great place to build and a reasonable place to host — until the bill, the limits, or the lock-in start to matter. How to get your code and data out, where to put them, and the Replit-specific things that break on the way.
Load Testing Your App Before Launch Day
Find out where your app breaks before your users do. What load, stress, spike, and soak tests reveal, writing a realistic k6 scenario with thresholds, reading p95 and error rates, finding the actual bottleneck, and the safety rules for testing without taking production — or a third-party API — down.
How to Launch Your First App: A Beginner's Launch Checklist
Your app works. Now what? A practical launch plan for first-time builders: the pre-launch checks, where to find your first users, how to launch on Product Hunt, Reddit, and Hacker News without getting ignored or banned, and what to watch in the first week.
How to Know When Your App Is Down (Before Your Users Tell You)
Most small apps find out about outages from an annoyed email. Three cheap layers — an uptime check, error tracking, and logs you can search — mean you hear first, and usually know why. What each one does, how to set it up in an afternoon, and how to avoid alerts you'll learn to ignore.
HTTP Caching Headers: Cache-Control, ETags, and Getting It Right
Most caching bugs are header bugs. How Cache-Control directives actually behave (max-age, s-maxage, no-cache vs no-store, private, immutable, stale-while-revalidate), how ETags and 304s work, Vary, and a practical header policy for static assets, HTML, APIs, and personalised pages.
How Much Does It Cost to Run an App? A Realistic Monthly Budget
Hosting, database, domain, email, AI usage, storage, and the tools around them. What each costs for a small app, what's free, where surprise bills come from, and three example budgets — from a side project to a small business with paying customers.
How Automatic SSL Actually Works (and Why It Sometimes Doesn't)
The padlock in the browser comes from a certificate that has to be issued, installed, and renewed on a schedule that keeps getting shorter. How Let's Encrypt and ACME prove you own a domain, how tools like Traefik and Caddy automate it, and the five reasons a certificate fails to issue or renew.
How to Keep API Keys Out of an AI-Built App
AI-generated code hardcodes API keys all the time — and 'put it in an environment variable' isn't enough if the variable ends up in the browser. Which keys are safe to expose, which never are, and how to fix a key that's already leaked.
How to Hand Off an AI-Built App to a Client
Freelancers and agencies are shipping client apps faster than ever with AI. The handoff is where projects go wrong: accounts in the wrong name, no documentation, and an open-ended support expectation. A checklist for handing over cleanly — and keeping the relationship profitable.
Set Up CI With GitHub Actions in Ten Minutes
Continuous integration runs your checks on every push and pull request, so broken code is caught before it merges — whoever, or whatever, wrote it. A working GitHub Actions workflow for a Node project, what each line does, how to make checks required, and the mistakes that make CI slow or insecure.
Feature Flags for Small Teams: Ship Code Without Shipping Features
Feature flags separate deploying code from releasing it: merge unfinished work safely, try features yourself first, roll out gradually, and switch things off without a redeploy. A simple implementation, when to use a service, and how to stop flags becoming clutter.
Does My App Need a Privacy Policy? A Plain-English Guide
If your app collects so much as an email address, the answer is almost certainly yes — and app stores, Google sign-in, and payment providers may require one anyway. What a privacy policy must cover, the other legal pages you'll need, cookie banners, and the practical obligations that come with them.
DNS Records Explained: A, CNAME, MX, and TXT for Beginners
Your domain's DNS settings page is a table of cryptic records. What A, AAAA, CNAME, MX, TXT, and NS records do, how subdomains work, what TTL means, why changes 'take time to propagate', and how to check what the world actually sees.
Dev, Staging, and Production Explained
Professional apps don't have one copy — they have several, so changes can be tried safely before real users see them. What development, staging, and production environments are, why they need separate databases and keys, and the simplest version that works for a small app.